Account Security
Protect your SCNX account with two-factor authentication (2FA). When 2FA is enabled, you'll need to verify your identity using an authenticator app, hardware security key, or recovery code before making sensitive changes.
Manage all security settings at scnx.app/user/security.
Setting Up Two-Factor Authentication
You can set up one or both of the following 2FA methods on your account:
Authenticator App (TOTP)
Use an authenticator app to generate time-based one-time codes. Popular options include:
- Ente Auth (open-source, cross-platform, with encrypted cloud backup)
- Authy (cross-platform with cloud sync)
- Google Authenticator
- Bitwarden (open-source password manager with built-in TOTP)
- Microsoft Authenticator
- Go to scnx.app/user/security
- In the Authenticator App section, follow the setup instructions
- Scan the QR code with your authenticator app
- Enter the code shown in your app to confirm setup
If you already have a security key set up, you can remove the authenticator app method. However, you must always have at least one 2FA method active.
Hardware Security Keys
Use a physical security key like a YubiKey or any FIDO2/WebAuthn compatible device. Security keys provide the strongest protection because they cannot be phished.
- Go to scnx.app/user/security
- In the Security Keys section, click Add Security Key
- Enter a name for your key (e.g. "YubiKey Blue")
- Follow your browser's prompt to register the key (you may need to touch or tap the key)
You can register up to 5 security keys on your account.
We recommend registering at least two security keys if possible - a primary key and a backup stored in a safe location.
Recovery Codes
Recovery codes are one-time-use backup codes that let you access your account if you lose your 2FA device. Each code can only be used once.
Generating Recovery Codes
- Go to scnx.app/user/security
- In the Recovery Codes section, click Generate Recovery Codes (or Regenerate if you already have codes)
- You'll receive 8 recovery codes
- Save them securely - copy them to a password manager or print them and store in a safe place
When you regenerate recovery codes, all previous codes are invalidated. Make sure to save the new codes immediately.
Recovery codes are your last resort for account access. If you lose both your 2FA device and your recovery codes, you'll need to go through the email-based reset process (7-day waiting period) or contact support.
Losing Access to Your 2FA
If you lose access to your authenticator app or security key, you have the following options:
Option 1: Use a Recovery Code
If you saved your recovery codes, use one to verify your identity. Each code works once.
Option 2: Email-Based 2FA Reset
If you've lost both your 2FA device and recovery codes, you can reset your 2FA via email:
- On the security page, initiate a 2FA reset by entering your account's email address
- You'll receive a confirmation email - click the link to confirm the reset
- A 7-day waiting period begins after confirmation
- After 7 days, your 2FA methods will be automatically removed, and you can set up new ones
The 7-day waiting period is a security measure - it gives you time to cancel the reset if someone else initiated it without your knowledge. You'll receive an email with a cancellation link when the reset is confirmed.
You can cancel a pending 2FA reset at any time before it executes from the security page.
Option 3: Contact Support
If email-based recovery isn't available (e.g. you've disabled it - see below), contact the SCNX support team for manual identity verification.
Disabling Email Self-Recovery
For maximum security, you can disable the email-based 2FA reset on your account. This prevents anyone - including someone who has access to your email - from resetting your 2FA through the self-service process.